IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 119 min read

Cyber Crimes, Ethical Issues & Legal Frameworks in IT

Unit 11 of Computer Security and Cyber Law explores the dark side of digital technology—cybercrimes like hacking, fraud, and cyberbullying—alongside ethical dilemmas in IT, legal frameworks in Nepal (e.g., Electronic Transaction Act 2008), and real-world cases (e.g., Ncell SIM fraud, Daraz phishing scams). Learn defini


Core Concepts: Definitions and Classifications

1. Cyber Crimes: Digital Offenses with Real Consequences

Cybercrimes are illegal activities committed using computers, networks, or digital devices. They exploit vulnerabilities in technology to harm individuals, organizations, or governments. Unlike traditional crimes, cybercrimes often cross borders, making them harder to trace and prosecute.

Types of Cyber Crimes (with Real-World Examples)

Definition: Unauthorized access to systems/dataExample: **Ncell SIM Fraud (2021)** – Rs. 200M+ stolen via dHackingDefinition: Deceptive practices to gain money/propertyExample: **Daraz Phishing Scams** – Fake 'order confirmationCyber FraudDefinition: Harassment via digital platforms (social media, Example: **WhatsApp Groups in Nepal** – Non-consensual shariCyber BullyingDefinition: Stealing personal info (Aadhaar, bank details) fExample: **eSewa Scams** – Fake 'tax refund' emails stealingIdentity TheftDefinition: Using tech to incite fear or disrupt servicesExample: **Nepal’s 2015 Website Defacements** – Political haCyber TerrorismCyber Crimes
Hierarchical classification of cyber crimes with Nepali examples

2. Ethical Issues in IT: Where Laws and Morality Collide

Ethics in IT refers to the principles guiding right/wrong behavior in technology use. Unlike laws (which are enforceable), ethics are moral guidelines. Key dilemmas include:

  • Privacy vs. Security: Should companies monitor employees’ emails for security?
  • Data Ownership: Who owns data collected by apps like Pathao (user location) or NEPSE (investor data)?
  • Whistleblowing: Is leaking a company’s security flaws (e.g., NTC’s outdated systems) ethical?

Ethical Theories in IT

Theory Application in IT Example
Utilitarianism Actions are right if they benefit the majority. Google’s AI Ethics Board: Decides if AI should prioritize user safety over profit.
Deontology Rules (e.g., GDPR) must be followed regardless of outcome. Nepal’s Electronic Transaction Act 2008: Mandates data protection laws.
Virtue Ethics Focuses on the character of the decision-maker. Ncell’s Ethical Hacking Program: Rewards employees for reporting bugs responsibly.
Rule-based (e.g., 'Do not hack')Nepalese Example: Cyber Crime Control Act's absolute bansDeontological EthicsOutcome-focused (e.g., 'Hack if it saves lives')Nepalese Example: Ethical hacking for national securityUtilitarianismCharacter-based (e.g., 'Be honest in coding')Nepalese Example: IT professional codes of conductVirtue EthicsEthical Frameworks in IT
Comparison of ethical theories applied to IT scenarios in Nepal

3. Cyber Laws in Nepal: Protecting the Digital Citizen

Nepal’s legal framework for cybercrimes includes:

  • Electronic Transaction Act 2008: Governs digital signatures, e-commerce, and cybercrime penalties.
  • Cyber Crime Control Act 2074 (2017): Criminalizes hacking, fraud, and cyberbullying.
  • Data Protection Bill (Draft): Aims to regulate how companies (e.g., Khalti, Daraz) handle user data.
Cyber Crime Legal Provision Penalty (Nepal) Real-World Case
Hacking Cyber Crime Control Act 2074 3–7 years imprisonment + fine Ncell SIM Fraudsters (2021): 5-year jail
Cyber Fraud Electronic Transaction Act 2008 Rs. 1M–10M fine + 3–10 years jail eSewa Scammers: Rs. 5M fine imposed
Cyber Bullying Cyber Crime Control Act 2074 Rs. 50K–500K fine + community service WhatsApp Group Harassment: Rs. 100K fine
Identity Theft Cyber Crime Control Act 2074 5–10 years jail + fine Khalti Data Leak (2020): 7 suspects arrested

4. Case Study: The Ncell SIM Fraud (2021)

Scenario: Hackers exploited Ncell’s Customer Relationship Management (CRM) system to clone SIMs, leading to Rs. 200M+ in losses. How It Happened:

  1. Phishing Attack: Employees clicked malicious links, revealing database credentials.
  2. SQL Injection: Hackers injected code to extract customer data (name, address, phone).
  3. SIM Swapping: Using stolen data, fraudsters activated duplicate SIMs to intercept OTPs.

Legal Outcome:

  • Ncell fined Rs. 10M for negligence.
  • 3 Hackers sentenced to 5 years jail under the Cyber Crime Control Act 2074.

Prevention Lessons:

  • Multi-Factor Authentication (MFA): Add OTP + biometrics for CRM access.
  • Employee Training: Simulate phishing attacks (e.g., Ncell’s "Phish Test" program).
  • Data Encryption: Store customer data in AES-256 encrypted databases.

5. Ethical Hacking vs. Cyber Crime: The Gray Area

Ethical hackers (or "white hats") legally test systems for vulnerabilities, while cybercriminals ("black hats") exploit them. The difference lies in intent and authorization.

Comparison Table

Aspect Ethical Hacker Cyber Criminal
Permission Explicit approval from the organization. No permission; operates secretly.
Goal Find and fix security flaws. Steal data, disrupt services, or extort.
Example in Nepal Ncell’s Bug Bounty Program: Pays Rs. 50K–5L for reporting flaws. Daraz Website Defacement (2020): Hackers replaced the homepage with political slogans.

6. Digital Citizenship: Your Role in Cyber Safety

Every user must follow digital ethics to prevent cybercrimes:

  • Protect Passwords: Use 12+ character passwords with symbols (e.g., K@thmandu$2024!).
  • Verify Sources: Check URLs (e.g., khalti.com vs. khalti-secure[.]com).
  • Report Suspicious Activity: Use Nepal Police’s Cyber Crime Unit (cybercrime@police.gov.np).
  • Educate Others: Teach family/friends about phishing (e.g., fake "NEPSE dividend" emails).
019.53958.578Password Strength65Phishing Awareness42Device Encryption78Backup Frequency33
Nepali students' cyber safety habits (2023 survey, %) – Identify weak areas!

Worked Example: Spotting a Phishing Email Email: "Your eSewa account is locked! Click here to verify." Red Flags:

  1. Generic Greeting: No personal name (e.g., "Dear User").
  2. Suspicious Link: Hover to see esewa-verification[.]scam[.]com.
  3. Urgency Tactics: "Account locked!" creates panic.

Action: Report to eSewa’s fraud team (fraud@esewa.com.np).


In the Real World

  1. Khalti’s Fraud Detection System

    • Idea Used: Anomaly Detection Algorithms (machine learning).
    • How: Khalti flags unusual transactions (e.g., Rs. 50K sent to a new merchant in 1 minute) and blocks them until verified.
    • Real Impact: Reduced fraud cases by 40% in 2023.
  2. Ncell’s Ethical Hacking Partnership with TU

    • Idea Used: Bug Bounty Programs.
    • How: Ncell invites IT students to hack their systems legally. Top finders get Rs. 1L prizes.
    • Real Impact: Patched 12 critical vulnerabilities in 2022.
  3. Daraz’s Two-Factor Authentication (2FA)

    • Idea Used: Multi-Layered Authentication.
    • How: After password entry, users must enter an OTP sent to their registered phone number.
    • Real Impact: Reduced account takeovers by 65% during the 2023 Dashain sales.

Exam Tip

This unit is highly theoretical but practical. Exams test:

  1. Definitions: Know the exact wording for terms like:
    • "Cyber bullying is the use of digital platforms to harass, threaten, or embarrass an individual or group."
    • "Ethical hacking is the authorized practice of testing systems for security vulnerabilities."
  2. Case Studies: Be ready to analyze Ncell SIM fraud, eSewa scams, or Daraz phishing in 5–10 marks.
  3. Legal Provisions: Memorize penalties from the Cyber Crime Control Act 2074 (e.g., hacking = 3–7 years).
  4. Ethical Dilemmas: Expect questions like:
    • "Is it ethical for a company to monitor employees’ work emails for security?" → Answer: Yes, if disclosed in the Employee Handbook (deontology).
  5. Preventive Measures: For any cybercrime, list 3 technical + 2 human solutions (e.g., for phishing: MFA + employee training).

Common Mistake: Describing cybercrimes without linking them to Nepal’s laws or real-world examples. Always tie answers to local cases (Ncell, Khalti, Daraz) or legal acts (Electronic Transaction Act 2008).


Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 11.

Discussion

Loading…